RocketChat/Rocket.Chat · error · Meteor.Error
error-not-allowed
error-not-allowed
Error message
Not Allowed
What it means
Thrown by POST /api/v1/rooms.export when the caller has mail-messages permission and the room exists, but the user record is missing or canAccessRoomAsync(room, user) is false: the caller cannot access that room. Typical for private channels, direct messages, and team rooms where the user is not a participant despite holding the export permission.
Solutions
- Run the export as a user who is a member of the target room
- Add the bot/user to the room before exporting
- Filter export targets to rooms the caller subscribes to (subscriptions.get)
- Catch and report 'no access' distinctly from 'room missing'
Example fix
// before
await bot.post('rooms.export', { rid: privateRid, type: 'file' }); // bot not in room
// after
const { subscription } = await bot.get('subscriptions.get', { rid: privateRid }).catch(() => ({ subscription: null }));
if (!subscription) await inviteBotToRoom(privateRid); // or use a member's token
await bot.post('rooms.export', { rid: privateRid, type: 'file' }); Defensive patterns
Strategy: validation
Validate before calling
const { subscription } = await sdk.get('subscriptions.get', { rid }).catch(() => ({ subscription: null }));
if (!subscription) throw new Error(`caller cannot access room ${rid} — join it or use a member token`); Try / catch
try {
await sdk.post('rooms.export', { rid, type: 'file' });
} catch (e: any) {
if (e?.response?.data?.errorType === 'error-not-allowed') {
// no room access: invite the bot/user, or re-run with a member's credentials
}
throw e;
} Prevention
- Add export bots as members of the rooms they must cover
- Filter export targets by the caller's subscription list
- Don't assume mail-messages implies room access
When it happens
Trigger: POST rooms.export with an admin token that has mail-messages but targets a private room that admin is not in (when access checks apply); a bot exporting a DM between two other users; a user removed from a private channel retrying an export.
Common situations: Export tooling assumed to be omniscient because it has the permission, only to hit room-access rules; offboarded users' queued exports firing after removal; bots granted broad permissions but never added to private rooms.
Related errors
- error-action-not-allowed
- error-cannot-delete-team-channel
- error-invalid-dates
- error-invalid-recipient
- error-invalid-room
AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-08-18).
Data as JSON: /api/errors/245accf3c37f3c66.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/server/api/v1/rooms.ts:1027
401: validateUnauthorizedErrorResponse,
},
},
async function action() {
const { rid, type } = this.bodyParams;
if (!(await hasPermissionAsync(this.user, 'mail-messages', rid))) {
throw new Meteor.Error('error-action-not-allowed', 'Mailing is not allowed');
}
const room = await Rooms.findOneById(rid);
if (!room) {
throw new Meteor.Error('error-invalid-room');
}
const user = await Users.findOneById(this.userId);
if (!user || !(await canAccessRoomAsync(room, user))) {
throw new Meteor.Error('error-not-allowed', 'Not Allowed');
}
if (type === 'file') {
const { dateFrom, dateTo } = this.bodyParams;
const { format } = this.bodyParams;
const convertedDateFrom = dateFrom ? new Date(dateFrom) : new Date(0);
const convertedDateTo = dateTo ? new Date(dateTo) : new Date();
convertedDateTo.setDate(convertedDateTo.getDate() + 1);
if (convertedDateFrom > convertedDateTo) {
throw new Meteor.Error('error-invalid-dates', 'From date cannot be after To date');
}
void dataExport.sendFile(
{
rid,
format,View on GitHub (pinned to e4b8178b20)